Improper Neutralization of Input During Web Page...
Moderate severity
Unreviewed
Published
Oct 27, 2025
to the GitHub Advisory Database
•
Updated Nov 13, 2025
Description
Published by the National Vulnerability Database
Oct 27, 2025
Published to the GitHub Advisory Database
Oct 27, 2025
Last updated
Nov 13, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev Activity Plus Reloaded for BuddyPress bp-activity-plus-reloaded allows Stored XSS.This issue affects Activity Plus Reloaded for BuddyPress: from n/a through <= 1.1.2.
References